Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yep. Defense in depth. Port-based VLAN at a minimum. Only total morons place their web-based and ssh remote/KVM management directly on the internet. Note that many Supermicro boards permit (as an option) to use the regular on-board NICs reducing the need to install a second or third cable for the BMC only adapter on mixed networks. Generally, one shouldn't be placing any box of any sort directly on the 'net unless it's hardened and behind sufficient network/application filtering.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: